Use the show l7 metadata-export health command to monitor the health states of the Layer 7 Metadata Event Exporter:
Connected—The Layer 7 Metadata Event Exporter is connected to the Splunk Enterprise server and is sending the network event logs.
Not Connected—The Layer 7 Metadata Event Exporter is not connected to the Splunk Enterprise server.
Connected (Not Authenticated)—The Layer 7 Metadata Event Exporter is connected to the Splunk Enterprise server, but authentication failed because of an invalid authorization token.
Not Applicable For UDP Protocol—If the Layer 7 Metadata Event Exporter is configured with the UDP transport protocol, you cannot view the health states.
Use the show l7metadata-export stats command to view how often network event logs are generated by the appliance and sent to the Splunk Enterprise server. The network event logs are measured in events per second (EPS). EPS is part of event logging that is used to monitor and record every instance of events that are generated by the appliance.
For details about these commands, see the CLI Command Reference.
Prerequisites
Administrator or Operator access to the Network Security appliance
A connection to the Splunk Enterprise server.
An active subscription to the Splunk Enterprise server.
Enable the Layer 7 Metadata Event Exporter. Use the
l7metadata-export enablecommand.
Go to CLI enable mode.
hostname > enable
View the health status of the Layer 7 Metadata Event Exporter.
hostname # show l7 metadata-export health
Go to CLI enable mode.
hostname > enable
View the details about how often network event logs are generated by the ADD Product Series appliance.
hostname # show l7metadata-export stats
Total L7-Meta-data Events Received: 269
Average EPS Rate: 0